2014 CVE Vulnerabilities
9,002 CVEs published in 2014.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2014-9732 | — | — | 7.2% | Jun 11, 2015 | The cabd_extract function in cabd.c in libmspack before 0.5 does not properly maintain decompression callbacks in certai... |
| CVE-2014-8607 | — | — | 0.9% | Jun 10, 2015 | The XCloner plugin 3.1.1 for WordPress and 3.5.1 for Joomla! provides the MySQL username and password on the command lin... |
| CVE-2014-8606 | — | — | 6.2% | Jun 10, 2015 | Directory traversal vulnerability in the XCloner plugin 3.1.1 for WordPress and 3.5.1 for Joomla! allows remote administ... |
| CVE-2014-8605 | — | — | 7.1% | Jun 10, 2015 | The XCloner plugin 3.1.1 for WordPress and 3.5.1 for Joomla! stores database backup files with predictable names under t... |
| CVE-2014-8604 | — | — | 7.1% | Jun 10, 2015 | The XCloner plugin 3.1.1 for WordPress and 3.5.1 for Joomla! returns the MySQL password in cleartext to a text box in th... |
| CVE-2014-8603 | — | — | 6.4% | Jun 10, 2015 | cloner.functions.php in the XCloner plugin 3.1.1 for WordPress and 3.5.1 for Joomla! allows remote administrators to exe... |
| CVE-2014-7872 | — | — | 1.0% | Jun 9, 2015 | Comodo GeekBuddy before 4.18.121 does not restrict access to the VNC server, which allows local users to gain privileges... |
| CVE-2014-9284 | — | — | 1.1% | Jun 9, 2015 | The Buffalo WHR-1166DHP 1.60 and earlier, WSR-600DHP 1.60 and earlier, WHR-600D 1.60 and earlier, WHR-300HP2 1.60 and ea... |
| CVE-2014-6284 | — | — | 1.8% | Jun 8, 2015 | SAP Adaptive Server Enterprise (ASE) before 15.7 SP132 and 16.0 before 16.0 SP01 allows remote attackers to bypass the c... |
| CVE-2014-7810 | — | — | 13.9% | Jun 7, 2015 | The Expression Language (EL) implementation in Apache Tomcat 6.x before 6.0.44, 7.x before 7.0.58, and 8.x before 8.0.16... |
| CVE-2014-0230 | — | — | 20.3% | Jun 7, 2015 | Apache Tomcat 6.x before 6.0.44, 7.x before 7.0.55, and 8.x before 8.0.9 does not properly handle cases where an HTTP re... |
| CVE-2014-8887 | — | — | 1.1% | Jun 7, 2015 | IBM Marketing Operations 7.x and 8.x before 8.5.0.7.2, 8.6.x before 8.6.0.8, 9.0.x before 9.0.0.4.1, 9.1.0.x before 9.1.... |
| CVE-2014-6222 | — | — | 1.5% | Jun 7, 2015 | Directory traversal vulnerability in IBM Marketing Operations 7.x and 8.x before 8.5.0.7.2, 8.6.x before 8.6.0.8, 9.0.x ... |
| CVE-2014-6175 | — | — | 1.0% | Jun 7, 2015 | Cross-site scripting (XSS) vulnerability in IBM Marketing Operations 7.x and 8.x before 8.5.0.7.2, 8.6.x before 8.6.0.8,... |
| CVE-2014-9201 | — | — | 1.6% | Jun 5, 2015 | Beckwith Electric M-6200 Digital Voltage Regulator Control with firmware before D-0198V04.07.00, M-6200A Digital Voltage... |
| CVE-2014-9721 | — | — | 2.5% | Jun 3, 2015 | libzmq before 4.0.6 and 4.1.x before 4.1.1 allows remote attackers to conduct downgrade attacks and bypass ZMTP v3 proto... |
| CVE-2014-8391 | — | — | 5.5% | Jun 2, 2015 | The Web interface in Sendio before 7.2.4 does not properly handle sessions, which allows remote authenticated users to o... |
| CVE-2014-0999 | — | — | 6.7% | Jun 2, 2015 | Sendio before 7.2.4 includes the session identifier in URLs in emails, which allows remote attackers to obtain sensitive... |
| CVE-2014-9727 | — | — | 71.6% | May 29, 2015 | AVM Fritz!Box allows remote attackers to execute arbitrary commands via shell metacharacters in the var:lang parameter t... |
| CVE-2014-6628 | — | — | 1.6% | May 28, 2015 | Aruba Networks ClearPass Policy Manager (CPPM) before 6.5.0 allows remote administrators to execute arbitrary code via u... |
| CVE-2014-9715 | — | — | 0.4% | May 27, 2015 | include/net/netfilter/nf_conntrack_extend.h in the netfilter subsystem in the Linux kernel before 3.14.5 uses an insuffi... |
| CVE-2014-9710 | — | — | 0.3% | May 27, 2015 | The Btrfs implementation in the Linux kernel before 3.19 does not ensure that the visible xattr state is consistent with... |
| CVE-2014-8147 | — | — | 23.2% | May 25, 2015 | The resolveImplicitLevels function in common/ubidi.c in the Unicode Bidirectional Algorithm implementation in ICU4C in I... |
| CVE-2014-8146 | — | — | 24.3% | May 25, 2015 | The resolveImplicitLevels function in common/ubidi.c in the Unicode Bidirectional Algorithm implementation in ICU4C in I... |
| CVE-2014-8927 | — | — | 1.3% | May 25, 2015 | Common Inventory Technology (CIT) before 2.7.0.2050 in IBM License Metric Tool 7.2.2, 7.5, and 9; Endpoint Manger for So... |
Check if your code is affected by 2014 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now